Build Your Lab badge
Set up the tools and practice targets you will use for everything else — an intercepting proxy and two deliberately-vulnerable apps — all free and running on your own machine.
| # | Exercise | Difficulty | Tier |
|---|---|---|---|
| 1 |
Offline Lab: See & Edit Real Requests (Intercepting Proxy)
Install a local intercepting proxy, route your browser through it, and watch — then modify — the real HTTP requests behind a page you control. The tool every web tester lives in. |
Easy | Free |
| 2 |
Offline Lab: Your First Local Target (DVWA)
Download and run a deliberately-vulnerable web app on your own machine, then practise the bugs you have learned against it. No internet target involved. |
Easy | Free |
| 3 |
Offline Lab: A Modern Target (OWASP Juice Shop)
Run OWASP Juice Shop — a modern single-page web app full of real-world bugs — on your own machine and learn to recon and poke a live application you control. |
Medium | Free |